Описание
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
Ссылки
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Broken LinkVendor Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Broken LinkVendor Advisory
- Third Party Advisory
- US Government Resource
- US Government Resource
Уязвимые конфигурации
Одно из
EPSS
10 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure gateway. This vulnerability has been exploited in the wild.
Уязвимость VPN-шлюза корпоративных сетей Pulse Connect Secure, связанная с ошибками аутентификации, позволяющая нарушителю выполнить произвольный код
EPSS
10 Critical
CVSS3
7.5 High
CVSS2